Back to skill

Security audit

Commitment and Consistency

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed thinking aid for analyzing commitment and consistency effects, with no executable behavior or hidden access.

This skill appears safe to install as a reasoning template. Users should still apply care when using commitment techniques in sales, onboarding, or persuasion contexts, since the content itself notes that ethical use depends on transparency, user benefit, and clear exits.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Skill Enumeration

Medium
Category
Agent Snooping
Content
>
> — Cialdini (1984/2006), p. 109.

This is the operational version of the [`sunk-cost-fallacy`](../skills/sunk-cost-fallacy/SKILL.md) defense applied to social commitments.

**Modern applications** are extensive:
Confidence
24% confidence
Finding
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.